shipping production AI · since 2026 NAICS 541330 / 541511 / 541512 / 541519  ·  CMMC-aware
§ Writing·The Refinery Report·est. 2022
weekly · long-form · no marketing

Notes from a firm
that ships.

Practitioner deep-dives on AI engineering, eval harnesses, MCP server internals, red-team field notes, federal procurement realities. Written by people on the keyboard. No "Top 10 AI Trends" lists. How we research & review →

109 posts weekly cadence · Mondays 4,210 subscribers ↗ also on Substack
filter
§ Refinery Report· All posts
AI GovernanceThird-Party Risk

AI Vendor Risk Management Program for Banks and Fintechs

What an AI vendor risk management program for banks and fintechs looks like after the initial assessment: the monitoring cadence, ownership, and evidence a risk committee needs between reviews.

September 29, 2026
TRAIGATexas AI Law

Texas TRAIGA for Banks and Fintechs: What HB 149 Requires

Texas HB 149, the Responsible AI Governance Act, took effect January 1, 2026 and is now enforceable statewide. What it requires of banks, captive finance arms, insurers, and fintechs, the financial-institution safe harbo

September 24, 2026
AI SecurityRed Teaming

AI Red Teaming for Financial Services: Scope and Outsource

How a bank, fintech, or insurer scopes and outsources AI red teaming: the four scoping decisions to fix before an RFP, what belongs in the statement of work, and how to vet a red-team vendor as the third party it is.

September 22, 2026
AI GovernancePricing

AI Governance Consulting Pricing for Banks and Fintechs

What US banks and fintechs actually pay for AI governance consulting: published market-estimate ranges by engagement type, what's included at each tier, and the three drivers that move the price inside a range.

September 17, 2026
AI GovernanceBroker-Dealers

AI Use Inventory for Broker-Dealers and RIAs: Examiners

What FINRA and SEC examiners ask to see first in an AI-touching exam: the AI use inventory. What belongs in it, the fields it needs, and how it maps to Rule 3110, Rule 2210, Rule 4511, and Form ADV.

September 15, 2026
AI red teamblue team controls

How AI Red-Team Findings Become Blue-Team Controls

A practical, evidence-led way to turn an authorized AI red-team finding into a customer-owned control decision, implementation work, and scoped re-test.

August 29, 2026
AI GovernanceFinancial Services

US Treasury Financial Services AI Risk Framework for Banks

The US Treasury FS AI RMF, issued in February 2026, gives banks a 230-control-objective matrix for governing AI. Here is how to prioritize it against SR 26-2 and your existing model risk program.

August 1, 2026
CybersecurityCyber Insurance

Cyber Insurance Evidence Readiness Checklist

Underwriting questionnaires ask for attestations you have to be able to evidence. The artifacts to assemble before renewal, and how to answer what you cannot prove.

July 19, 2026
CybersecurityIncident Response

Incident Response Planning Without a Security Team

How an organization with no internal security function builds an incident response plan that works: decision rights, the first hour, contacts, and what to rehearse.

July 19, 2026
CybersecurityNIST CSF 2.0

NIST CSF 2.0 Roadmap for 50 to 500 Employees

A four-quarter sequence for adopting NIST CSF 2.0 at mid-market scale: scoping the Profile, choosing a Tier honestly, and ordering the work so each quarter funds the next.

July 19, 2026
CybersecurityRansomware Readiness

How to Prove Your Backups Will Actually Restore

A restore test is evidence; a backup job report is not. How to design a restore drill, what to record, and the recovery objectives the drill is meant to prove.

July 19, 2026
CybersecuritySecurity Leadership

vCISO vs MSP vs MDR: Who Owns What

A RACI for the three roles growing firms buy in the wrong order: who sets direction, who runs the estate, who watches the alerts, and where accountability actually sits.

July 19, 2026
CybersecurityVendor Risk

Vendor Security Review Checklist for SaaS Buyers

How to review a SaaS vendor's security before signing: tiering by data and dependency, reading an audit report properly, and the contract terms that outlive the questionnaire.

July 19, 2026
HealthcareHIPAA

HIPAA AI Governance Readiness: Program Behind the Boundary

A practical readiness checklist for healthcare organizations building an AI governance program under HIPAA: use-case inventory, BAA mapping, minimum-necessary scoping, Security Rule safeguards, and the evidence a review

July 5, 2026
FederalPublic Sector

Private AI Controls for Public-Sector Sensitive Workloads

A practical control checklist for federal and public-sector teams that have already decided a workload needs a private AI boundary: tenant isolation, access control, logging, supply-chain provenance, and a tested kill-sw

July 5, 2026
AI SecurityMCP Security

MCP Security Checklist: Pin, Hash, and Gate Drift

A vendor-neutral MCP security checklist: inventory and approve servers, pin the declared surface, hash tool definitions, scan for poisoning, and mediate at runtime.

June 14, 2026
AI SecurityOWASP LLM Top 10

OWASP LLM Top 10 Assessment: A Practitioner Guide

A practitioner's walkthrough of the OWASP LLM Top 10, each risk in a quotable definition, exactly how DSE tests for it, and one real failure pattern we see in the wild.

June 9, 2026
AI EngineeringRAG

Did Agents Kill Vector Search? A Scale-Dependent Answer

The 2026 take that filesystem agents killed vector databases is half right and dangerously oversimplified. The honest engineering answer depends on your scale threshold, and production converges on hybrid retrieval.

May 28, 2026
Context EngineeringSemantic Modeling

From Data to Context Engineering: The 2026 Semantic Reboot

While everyone obsesses over bigger models and faster GPUs, the real bottleneck in enterprise AI is sitting in plain sight: your agents have no idea what your data actually means. Here's why 2026 is the year context engi

January 8, 2026
AI TalentAI Systems Architecture

The AI Job Nobody's Hiring For (And Why It Costs Millions)

Companies are spending billions hiring AI talent, yet 95% of AI projects still fail to deliver ROI. The disconnect is a missing role almost nobody is hiring for: the AI Systems Architect, the person who orchestrates mode

January 2, 2026
Data EngineeringBig Data

Data Freshness and Timeliness in Modern Data Pipelines

In the evolving landscape of data engineering, ensuring the timeliness and freshness of data is paramount. The 'Watcher Framework' provides a strategic approach to managing these critical elements within data pipelines.

January 1, 2026
Data EngineeringBig Data

Informatica and Legacy Systems in Modern Data Engineering

In this analytical report, we dissect the challenges faced by enterprises using Informatica within the evolving landscape of modern data engineering. The article discusses critical drawbacks of using legacy ETL systems l

January 1, 2026
Data EngineeringBig Data

Unlocking the Uniformity of Scaled ClickHouse Deployments

The article discusses the intriguing uniformity observed in scaled ClickHouse deployments across various companies. Despite the diverse nature of businesses, a distinctive pattern emerges when scaling ClickHouse for data

January 1, 2026
AI StrategyInnovation

Strategic Insights from 2025''s Top Technology Narratives

The year 2025 brought forward pivotal stories in technology, as recorded by MIT Technology Review, which hold substantial strategic implications for industry leaders. From the unprecedented rise in generative AI tools an

December 29, 2025
AI StrategyInnovation

MIT Technology Review's Top 2025 Stories: Strategic Insights

In 2025, MIT Technology Review highlighted pivotal trends across AI, biotechnology, and energy sectors, offering crucial insights into emerging technologies. Key stories included AI's substantial energy consumption, brea

December 29, 2025
AI StrategyInnovation

Strategic Opportunities in the Evolving Climate Tech Landscape

In 2025, despite the grim overarching climate news, there were significant advancements in clean energy technologies, particularly in China and the United States. China's decoupling of economic growth from carbon emissio

December 29, 2025
Enterprise AIBusiness Strategy

Hardware Stress Signals: iRobot, Luminar, and Correlated Risk

Hardware breaks the same way across categories. Cash runs out before the cycle closes. Demand drops faster than factories can slow. When capital tightens and consumers hesitate, hardware companies take the hit together.

December 21, 2025
AI StrategyContent Moderation

The Viral Playbook: How AI Feeds Route Attention and Risk

A short viral clip is not novelty, it is repeatability. AI-driven feeds turn a single stunt into a supply chain. The same AI that industrializes harm can also reduce it, but only if platforms choose restraint over growth

December 21, 2025
AI ROIData Science

Data Science in 2025: From Generative AI Hype to Real ROI

In 2025, data did not just grow, it spilled over. 58% report exponential productivity gains from GenAI, yet fewer than 30% of CEOs are satisfied with ROI. Discover what actually worked: augmented analytics, synthetic dat

December 8, 2025
SEOGoogle AI

Gemini 3: Google's Next-Gen AI and Its Impact on SEO in 2026

Google launched Gemini 3 directly into Search in late 2025, ending the ten blue links era. With Deep Think reasoning, 1M token context, and multimodal processing, Gemini 3 fundamentally changes SEO. Learn the new require

December 8, 2025
Health PolicyACA

The 2025 Health Insurance Standoff and Government Shutdown

The federal government shutdown of Oct 1, 2025 became a health-policy showdown. Enhanced ACA subsidies at risk, immigrant-coverage rules in dispute, and market volatility created measurable affordability shocks, operatio

October 20, 2025
Workplace AIEmployee Psychology

The Tense Dynamic Between Employers and Employees Over AI Use

A startling 57% of employees globally hide their AI use from managers, while 48% have uploaded sensitive company data to public AI tools. This workplace tension reveals fundamental shifts in power dynamics and the evolvi

September 25, 2025
Post Labor EconomicsUniversal Basic Income

Post Labor Economics: How AI and UBI Can Architect a Post-Labor Economy

AI and robotics are accelerating beyond manufacturing into white-collar and creative domains. A growing evidence base from UBI pilots suggests moderate income floors can improve well-being without mass labor market exit,

September 25, 2025
§ By topic cluster· Four pillars

AI Security & Governance

Practitioner writing on AI security and governance: prompt injection, agent abuse, RAG poisoning, and readiness against NIST AI RMF, the EU AI Act, and ISO 42001. When it is time to test a live system, start with a fixed-fee AI security assessment.

Enterprise AI ROI & Failure

On enterprise AI ROI and the AI failure crisis: why most projects stall, and what separates the 5% that ship from the 95% that do not: rescue playbooks and the systems view of production AI. See how we scope production AI engagements.

Data Engineering & Architecture

Field notes on data engineering and architecture: pipelines, data quality, lakehouse and warehouse design, and the foundations production AI actually stands on. This is what senior-only data engineering looks like.

Industry & Society

Wider-lens analysis of how AI is reshaping work, policy, media, and society: the context that frames every technical decision.

Get the Report before Monday.

One long-form post a week, written by whichever engineer was closest to the work. No tracking pixels, no promo. Unsubscribe in one click.

~12 issues / quarter